Skip to content

Runbook 02 — Enterprise Cloud Security Assessment

Item Details
Runbook ID CPS-RB-002
Category Enterprise Cloud Security Assessment
Audience Cloud Security Engineers, Cloud Penetration Testers, Red Teams, Security Consultants
Estimated Duration 1–5 Days
Environment AWS, Azure, Google Cloud, Kubernetes
Prerequisites Completed Engagement Preparation Checklist

This runbook provides a structured methodology for performing an enterprise cloud security assessment.

Rather than focusing on individual vulnerabilities, this assessment evaluates the overall security posture of an organization’s cloud environment by reviewing:

  • Identity Security
  • Cloud Infrastructure
  • Storage
  • Compute
  • Networking
  • Kubernetes
  • Containers
  • Logging & Monitoring
  • Cloud Governance
  • Attack Paths
  • Business Risk

This is the same assessment workflow followed by enterprise consulting organizations during professional cloud penetration testing engagements.


CloudNova Technologies has been engaged to perform a comprehensive security assessment of FinSecure Bank Ltd before its production migration.

The customer operates:

  • AWS Organization
  • Multiple AWS Accounts
  • Amazon EKS
  • Docker
  • AWS Lambda
  • Terraform
  • GitHub Enterprise
  • Jenkins CI/CD
  • Microsoft Entra ID

Your objective is to identify security weaknesses and provide executive recommendations.


Kick-off Meeting
Architecture Review
Asset Discovery
Identity Assessment
Network Assessment
Compute Assessment
Storage Assessment
Container & Kubernetes Assessment
Logging & Monitoring Review
Attack Path Analysis
Risk Assessment
Executive Report
Customer Presentation

Confirm assessment scope and customer expectations.

Review:

  • Rules of Engagement
  • Statement of Work
  • Cloud Accounts
  • Timeline
  • Deliverables
  • Communication Plan
  • Scope confirmed
  • Customer contacts verified
  • Testing window confirmed
  • Communication channels established
  • Architecture documents received

Review the enterprise cloud architecture.

  • AWS Organization Structure
  • AWS Accounts
  • Azure Subscriptions
  • Google Cloud Projects
  • Kubernetes Clusters
  • VPC Architecture
  • Network Topology
  • CI/CD Pipelines
  • IAM Architecture

  • Architecture Review Notes
  • Initial Risk Assessment
  • Critical Asset Inventory

Enumerate cloud assets.

AWS

Terminal window
aws resourcegroupstaggingapi get-resources

Review:

  • EC2
  • Lambda
  • EKS
  • RDS
  • S3
  • VPC
  • IAM
  • CloudTrail

  • Compute identified
  • Storage identified
  • Networking documented
  • IAM inventory completed
  • Kubernetes inventory created

Review:

  • IAM Users
  • IAM Roles
  • IAM Policies
  • IAM Groups
  • Federation
  • MFA
  • Access Keys
  • Service Accounts

Commands

Terminal window
aws iam list-users
aws iam list-roles
aws iam list-policies

Review:

  • Administrator accounts
  • Wildcard permissions
  • Trust policies
  • Privilege escalation opportunities

  • Administrator without MFA
  • Root account usage
  • Long-lived credentials
  • Cross-account trust
  • iam:PassRole permissions

Review:

  • VPCs
  • Security Groups
  • NACLs
  • Route Tables
  • Internet Gateways
  • NAT Gateways
  • VPC Endpoints
  • VPN Connections

Commands

Terminal window
aws ec2 describe-security-groups
aws ec2 describe-vpcs
aws ec2 describe-route-tables

Review:

  • Public exposure
  • Open management ports
  • Network segmentation
  • Internet-facing workloads

  • SSH (22) exposed
  • RDP (3389) exposed
  • Database ports publicly accessible
  • Missing segmentation

Review:

  • EC2
  • Auto Scaling Groups
  • AMIs
  • Launch Templates

Commands

Terminal window
aws ec2 describe-instances

Assess:

  • Public IPs
  • Instance Profiles
  • IMDS Version
  • EBS Encryption
  • Patch Status
  • Endpoint Protection

  • IMDSv1 enabled
  • Administrator instance roles
  • Public EC2
  • Unencrypted volumes

Review:

  • Amazon S3
  • EBS
  • EFS
  • Backup Storage

Commands

Terminal window
aws s3 ls

Review:

  • Public buckets
  • Bucket policies
  • Encryption
  • Versioning
  • Object Lock
  • Logging

  • Public access
  • Missing encryption
  • Missing logging
  • Cross-account exposure

Phase 8 — Kubernetes Security Assessment

Section titled “Phase 8 — Kubernetes Security Assessment”

Review:

  • Amazon EKS
  • Nodes
  • Pods
  • RBAC
  • Service Accounts
  • Network Policies
  • Secrets
  • Admission Controllers

Commands

Terminal window
kubectl get nodes
kubectl get pods -A
kubectl get secrets -A
kubectl get clusterroles

Review:

  • Root containers
  • Privileged Pods
  • Cluster-admin accounts
  • Secrets exposure

  • Privileged workloads
  • Public Dashboard
  • Missing Network Policies
  • Weak RBAC

Review:

  • Docker Images
  • Base Images
  • Vulnerabilities
  • Image Signing
  • Registry Security

Run:

Terminal window
trivy image IMAGE_NAME

Review:

  • Critical CVEs
  • Outdated packages
  • Root user
  • Sensitive files

  • Critical vulnerabilities
  • Unsigned images
  • Running as root
  • Hardcoded secrets

Phase 10 — Logging & Monitoring Assessment

Section titled “Phase 10 — Logging & Monitoring Assessment”

Review:

  • CloudTrail
  • CloudWatch
  • AWS Config
  • GuardDuty
  • Security Hub
  • Security Lake

Commands

Terminal window
aws cloudtrail describe-trails

Review:

  • Audit coverage
  • Log retention
  • Alerting
  • Multi-region logging

  • Logging disabled
  • Missing GuardDuty
  • No AWS Config
  • No alerting

Develop realistic attack chains.

Example

Internet
Public Application
Container
Service Account
IAM Role
Amazon S3
Customer Data

Document:

  • Initial Access
  • Privilege Escalation
  • Lateral Movement
  • Data Access
  • Business Impact

Prioritize findings.

Severity Description
Critical Immediate compromise likely
High Significant business risk
Medium Moderate security weakness
Low Best practice improvement
Informational Observation only

Assign:

  • CVSS (if applicable)
  • Business Impact
  • Likelihood
  • Overall Risk

Prepare:

Include:

  • Overall security posture
  • Major risks
  • Executive recommendations

For every finding include:

  • Description
  • Evidence
  • Impact
  • Likelihood
  • Risk Rating
  • Remediation

Illustrate:

Identity
Privilege Escalation
Cloud Resources
Sensitive Data

  • Enable MFA
  • Remove public access
  • Rotate credentials
  • Remove wildcard IAM permissions
  • Harden Kubernetes
  • Implement Network Policies
  • Enable CloudTrail
  • Configure GuardDuty
  • CSPM
  • Continuous Compliance
  • Runtime Detection
  • Zero Trust Architecture

Produce:

  • Executive Summary
  • Technical Assessment Report
  • IAM Assessment
  • Network Assessment
  • Storage Assessment
  • Compute Assessment
  • Kubernetes Assessment
  • Attack Surface Diagram
  • Attack Path Diagram
  • Risk Register
  • Remediation Roadmap
  • Executive Presentation

Verify:

  • Architecture reviewed
  • Asset inventory completed
  • IAM assessed
  • Networking assessed
  • Compute assessed
  • Storage assessed
  • Kubernetes assessed
  • Containers assessed
  • Logging reviewed
  • Attack paths documented
  • Risks prioritized
  • Executive report completed

Typical enterprise findings include:

  • Administrator accounts without MFA
  • Overly permissive IAM policies
  • Public S3 buckets
  • Public EC2 instances
  • Weak Security Groups
  • IMDSv1 enabled
  • Privileged Kubernetes Pods
  • Cluster-admin service accounts
  • Missing Network Policies
  • Hardcoded credentials
  • Critical container vulnerabilities
  • CloudTrail disabled

  • Review identity before infrastructure.
  • Validate every finding with evidence.
  • Focus on realistic attack paths.
  • Prioritize business impact over technical complexity.
  • Use least privilege throughout the cloud environment.
  • Review Kubernetes as part of every assessment.
  • Communicate findings clearly to both technical and executive stakeholders.

At the completion of this runbook you should have:

  • Enterprise Cloud Security Assessment Report
  • Executive Summary
  • Technical Findings Report
  • Cloud Asset Inventory
  • IAM Review
  • Network Review
  • Storage Review
  • Kubernetes Review
  • Attack Path Analysis
  • Risk Register
  • Executive Presentation
  • Remediation Roadmap

This runbook is successfully completed when:

  • All cloud services have been assessed.
  • Critical attack paths have been identified.
  • Findings have been validated with evidence.
  • Business risks have been documented.
  • Actionable remediation guidance has been provided.
  • Executive and technical reports have been delivered to the customer.

➡️ Runbook 03 — Enterprise Cloud Attack Path & Executive Risk Assessment